- Reviews & Ratings Policy
- Gotorex Product Safety & Compliance Policy
- Security & Responsible Disclosure Policy
- Prohibited & Restricted Products Policy
- International Trade Compliance Policy
- Legal Notices / Company Information
- Refund, Return & Cancellation Policy
- Marketing & Communications Policy
- Marketplace Transparency Policy
- Taxes/VAT/GST & Customs Policy
- Buyer Protection Policy
- Seller Verification Policy
- Payments & Pricing Policy
- Dispute Resolution Policy
- Copyright/DMCA Policy
- Promotions & Coupon Terms
- Intellectual Property Policy
- Shipping & Delivery Policy
- Gotorex Seller Agreement
- Accessibility Statement
- Terms & Conditions
- Track You Order
- Work With Us
- Cookie Policy
- Privacy Policy
- Our Partners
- Contact Us
- About Us
- FAQs
Gotorex Security & Responsible Disclosure Policy
Effective Date: 21 August 2026
Last Updated: 21 August 2026
This Security & Responsible Disclosure Policy applies to www.gotorex.com, a multi-seller international e-commerce marketplace operated from South Africa.
Gotorex Business Address:
<span style="color:red">[INSERT FULL REGISTERED BUSINESS ADDRESS, SOUTH AFRICA]</span>
Security & Legal Contact: admin@gotorex.com
Gotorex takes the security of its website, marketplace, customer information and seller information seriously. This Policy explains how security concerns may be reported and how Gotorex may respond.
1. Our Security Commitment
Gotorex aims to use reasonable technical and organisational safeguards to protect its systems and information against:
- Unauthorised access;
- Loss or misuse of information;
- Unauthorised alteration;
- Destruction;
- Fraud; and
- Other reasonably foreseeable security threats.
No website, system or transmission over the internet can be guaranteed to be completely secure.
2. Responsible Disclosure
Security researchers and other individuals are encouraged to report genuine security vulnerabilities responsibly.
Reports should be sent to:
Please provide enough information for Gotorex to understand and reproduce the reported issue.
Where reasonably possible, include:
- A description of the vulnerability;
- The affected website, page or feature;
- Steps required to reproduce the issue;
- Potential security impact;
- Screenshots or other non-sensitive evidence; and
- Your contact information for follow-up.
3. Responsible Testing
Security testing must be conducted responsibly and only to the extent reasonably necessary to demonstrate a vulnerability.
Researchers must not:
- Access, copy or disclose unnecessary personal information;
- Access another person's account without permission;
- Modify or delete data;
- Disrupt or degrade Gotorex systems;
- Conduct denial-of-service attacks;
- Use malware;
- Conduct social engineering against Gotorex personnel or customers;
- Attempt to obtain payment information;
- Extort or threaten Gotorex;
- Publicly disclose a vulnerability before allowing reasonable time for investigation; or
- Continue testing after Gotorex has requested that testing stop.
Testing must not intentionally interfere with customers, sellers, suppliers or other users.
4. Personal Information
If a security vulnerability exposes personal information, researchers must avoid collecting, retaining, copying or disclosing more information than reasonably necessary to demonstrate the issue.
Any personal information obtained accidentally should be securely deleted as soon as reasonably practicable.
Security incidents involving personal information may be handled in accordance with applicable data-protection and breach-notification laws.
5. What to Report
Security concerns may include:
- Unauthorised access vulnerabilities;
- Authentication or authorisation weaknesses;
- Exposure of sensitive information;
- Payment-security vulnerabilities;
- Account-takeover vulnerabilities;
- Significant software vulnerabilities;
- Security misconfigurations; or
- Other vulnerabilities that could materially affect Gotorex users or systems.
6. Issues Generally Outside This Policy
The following may not qualify as security vulnerabilities unless they create a demonstrable material security risk:
- Spam;
- Social-engineering attempts against third parties;
- Self-inflicted account issues;
- Reports without sufficient information to investigate;
- General website feedback;
- Automated vulnerability scans that create excessive traffic;
- Known third-party vulnerabilities outside Gotorex's control; or
- Theoretical issues without a reasonably demonstrated security impact.
7. Gotorex's Response
Gotorex may:
- Acknowledge a report;
- Investigate the issue;
- Request additional information;
- Take corrective action;
- Restrict affected functionality;
- Work with affected sellers or service providers;
- Notify affected individuals where legally required; and
- Report matters to competent authorities where required or appropriate.
Response and remediation times may vary according to the severity and complexity of the issue.
8. Confidentiality & Disclosure
Researchers should provide Gotorex with reasonable time to investigate and address a vulnerability before publicly disclosing technical details.
Gotorex may communicate with researchers regarding remediation where appropriate.
Nothing in this Policy prevents a person from exercising rights that cannot legally be waived or restricted.
9. Security Incidents
If Gotorex becomes aware of a security incident, it may take reasonable steps to contain, investigate and remediate the incident.
Where legally required, Gotorex may notify:
- Affected customers;
- Sellers;
- Business partners;
- Regulators;
- Law-enforcement authorities; or
- Other appropriate parties.
Notification requirements depend on the nature of the incident and applicable law.
10. Account Security
Customers and sellers are responsible for maintaining the security of their accounts, including:
- Keeping passwords confidential;
- Using appropriate account-security measures;
- Not sharing login credentials; and
- Reporting suspected unauthorised account activity promptly.
Suspected account compromise should be reported to:
11. Payment Security
Payment information may be processed by third-party payment providers.
Gotorex may not directly store or process all payment-card information and may rely on specialised payment providers and security controls.
Customers should never send full payment-card numbers, passwords, authentication codes or other sensitive credentials by email.
12. Third-Party Services
Gotorex may use third-party providers for services such as:
- Payments;
- Hosting;
- Shipping;
- Analytics;
- Security;
- Communications; and
- Marketplace functionality.
Security practices of third parties may be governed by their own policies and contractual obligations.
Gotorex may take reasonable steps to select and manage service providers appropriate to the nature of the services provided.
13. Fraud & Abuse
Gotorex may monitor transactions and account activity for legitimate security, fraud-prevention and compliance purposes.
Where reasonably necessary and legally permitted, Gotorex may:
- Restrict accounts;
- Delay transactions;
- Cancel transactions;
- Request verification;
- Restrict seller activity; or
- Report suspected unlawful activity.
14. Damaged Products, Returns & Refunds
Security reports should not be sent through product-return or refund channels.
For damaged products, returns or refund requests, customers should contact:
Customers may be required to provide reasonable evidence, including photographs, videos, order information or other relevant documentation.
Where inspection is required, the time required to investigate and resolve the matter depends on the circumstances and complexity of the case, subject to mandatory legal requirements.
15. Shipping & Security
Shipping times vary according to the seller, supplier, warehouse, carrier and destination.
Some products may be delivered as quickly as 1–3 business days in countries such as the United States, while other products may take substantially longer.
Security, customs or fraud checks may occasionally affect processing or delivery where legally permitted.
16. No Guarantee
Although Gotorex takes reasonable security measures, no online service can guarantee complete protection against every security threat.
Customers and sellers acknowledge that internet-based services involve inherent security risks.
This does not exclude any mandatory legal obligations imposed on Gotorex.
17. Policy Changes
Gotorex may update this Policy as its security practices, technology, marketplace or legal requirements change.
The latest version will be published on www.gotorex.com.
18. Contact & Responsible Disclosure
Gotorex
Security Email: admin@gotorex.com
Business Address:
<span style="color:red">[INSERT FULL REGISTERED BUSINESS ADDRESS, SOUTH AFRICA]</span>
Website: www.gotorex.com